You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Four open defects in hyperpolymath/rsr-template-repo are one missing check: a repository
asserting provenance it does not have, with nothing able to notice.
chore(deps): bump github/codeql-action from 4.35.2 to 4.35.3 #201 — a minted Julia child's generated CLAUDE.md arrival pack still claimed
IS: "Canonical RSR-compliant repository template", the template's UUID a5ea1382-… and clade rm, while its own descriptiles said Julia/knot-theory,
UUID a6cbd9d9-…, clade dx.
These are not stylistic drift. A contributor following #200's instructions clones the
wrong project; a child that believes it is the template mis-reports its own identity to
every agent that reads it.
Why Hypatia should own the detection
This is exactly Hypatia's remit — a rule-shaped, estate-wide, machine-detectable
invariant with a low false-positive rate. The signals are structural and local; none
needs the template checkout.
Proposed rules. Names are suggestions; the estate's module/type naming should win.
Rule
Detects
Signal
template_contract/TC001
missing provenance
repo has no .machine_readable/PROVENANCE.a2ml but has instantiation markers (e.g. no archetypes/, has MINT-PROVENANCE/PROVENANCE refs)
template_contract/TC002
self-parent
template_repo equals the repo's own owner/name
template_contract/TC003
unresolved parent pin
template_branch/template_commit/template_tree absent or UNASSIGNED on a published repo
template_contract/TC004
leaked template branch
a non-default branch with no merge-base against the default branch
template_contract/TC005
stale template identity
a file asserts template purpose/UUID (“canonical … template”, the template's UUID) in a repo that is not the template
template_contract/TC006
dangling shipped path
shipped content references a path that does not exist in the child (the MINT-PROVENANCE.a2ml case)
TC004 is the highest-value and cheapest: git merge-base --is-ancestor / empty
merge-base against the default branch. It is a pure-graph test, no heuristics.
TC005/TC006 are the #200/#201/#202 family and are text-level, so they can be
advisory-with-confidence like the existing RE-series.
Reference implementation
rsr-template-repo PR #207 adds scripts/check-template-conformance.sh, which implements
T1–T4 (TC001–TC004) with a positive control and five negative controls in tests/workflows/template_conformance_test.sh. Two bugs in that checker were caught by its
own negative controls before commit — including one that silently disabled the self-parent
check. Lifting the T-logic into a Hypatia rule module is the natural next step.
Verified against a real child, not fixtures: metadatastician/knot-knot → T1/T2/T4 pass;
T3 fails on template_branch/template_tree, which genuinely do not exist in a repo minted
before that commit, and whose provenance records minted_by = "hand" (hardcoded — see below).
A finding that needs Hypatia's own attention
repo-init hardcoded minted_by = "hand", so every scripted mint falsely claimed to be
hand-minted. Any rule that reasons about which minting path ran would have been reading a
lie. Fixed in PR #207, but it is a live example of the class Hypatia is meant to catch:
a field that is present, plausible, and wrong.
Acceptance
T1–T4 (or the estate's naming) implemented as rule modules with stated confidence.
Estate sweep over the ~352 public repos, report-only, producing counts per rule and a
reviewed repair plan — not an unattended rewrite.
TC004 results cross-checked against provenance, so children with legitimate
multi-branch contracts are not flagged.
Related
rsr-template-repo#200, #201, #202, #203, and PR #207. Lifecycle ownership per standards#634 (template composition) and standards#636 (lifecycle orchestration):
Hypatia detects and proposes; it must not silently merge unrelated histories.
The class
Four open defects in
hyperpolymath/rsr-template-repoare one missing check: a repositoryasserting provenance it does not have, with nothing able to notice.
CONTRIBUTING.mddescribed a different repository entirely(
language-bridges), with a hardcoded clone URL.CLAUDE.mdarrival pack still claimedIS: "Canonical RSR-compliant repository template", the template's UUID
a5ea1382-…and claderm, while its own descriptiles said Julia/knot-theory,UUID
a6cbd9d9-…, cladedx.JET.test_package(path=…, julia_version=…),an API removed in JET v0.12.0. Dead on arrival; no check executed it.
metadatastician/knot-knotwithno common ancestor. Git proved both trees are
c8cca962…— byte/mode/path identical.These are not stylistic drift. A contributor following #200's instructions clones the
wrong project; a child that believes it is the template mis-reports its own identity to
every agent that reads it.
Why Hypatia should own the detection
This is exactly Hypatia's remit — a rule-shaped, estate-wide, machine-detectable
invariant with a low false-positive rate. The signals are structural and local; none
needs the template checkout.
Proposed rules. Names are suggestions; the estate's module/type naming should win.
template_contract/TC001.machine_readable/PROVENANCE.a2mlbut has instantiation markers (e.g. noarchetypes/, hasMINT-PROVENANCE/PROVENANCErefs)template_contract/TC002template_repoequals the repo's ownowner/nametemplate_contract/TC003template_branch/template_commit/template_treeabsent orUNASSIGNEDon a published repotemplate_contract/TC004template_contract/TC005template_contract/TC006MINT-PROVENANCE.a2mlcase)TC004is the highest-value and cheapest:git merge-base --is-ancestor/ emptymerge-base against the default branch. It is a pure-graph test, no heuristics.
TC005/TC006are the #200/#201/#202 family and are text-level, so they can beadvisory-with-confidence like the existing RE-series.
Reference implementation
rsr-template-repoPR #207 addsscripts/check-template-conformance.sh, which implementsT1–T4 (TC001–TC004) with a positive control and five negative controls in
tests/workflows/template_conformance_test.sh. Two bugs in that checker were caught by itsown negative controls before commit — including one that silently disabled the self-parent
check. Lifting the T-logic into a Hypatia rule module is the natural next step.
Verified against a real child, not fixtures:
metadatastician/knot-knot→ T1/T2/T4 pass;T3 fails on
template_branch/template_tree, which genuinely do not exist in a repo mintedbefore that commit, and whose provenance records
minted_by = "hand"(hardcoded — see below).A finding that needs Hypatia's own attention
repo-inithardcodedminted_by = "hand", so every scripted mint falsely claimed to behand-minted. Any rule that reasons about which minting path ran would have been reading a
lie. Fixed in PR #207, but it is a live example of the class Hypatia is meant to catch:
a field that is present, plausible, and wrong.
Acceptance
that could never fire (chore(deps): bump docker/build-push-action from 6.18.0 to 6.19.2 #49 invisible-character gate matched nothing; chore(deps): bump docker/login-action from 3.7.0 to 4.0.0 #64 Hypatia gate
was unconditionally vacuous). A rule without a negative control is not a rule.
reviewed repair plan — not an unattended rewrite.
TC004results cross-checked against provenance, so children with legitimatemulti-branch contracts are not flagged.
Related
rsr-template-repo#200, #201, #202, #203, and PR #207. Lifecycle ownership perstandards#634(template composition) andstandards#636(lifecycle orchestration):Hypatia detects and proposes; it must not silently merge unrelated histories.